Bit-flip jailbreak attacks succeed easily on FP16 language models, are slowed but not stopped by FP8/INT8 quantization, and FP16-induced jailbreaks often survive post-attack quantization to 8-bit formats.
An adversarial perspective on machine unlearning for ai safety, 2025
1 Pith paper cite this work. Polarity classification is still indexing.
1
Pith paper citing it
citation-role summary
background 1
citation-polarity summary
fields
cs.CR 1years
2025 1verdicts
CONDITIONAL 1roles
background 1polarities
support 1representative citing papers
citing papers explorer
-
On Jailbreaking Quantized Language Models Through Fault Injection Attacks
Bit-flip jailbreak attacks succeed easily on FP16 language models, are slowed but not stopped by FP8/INT8 quantization, and FP16-induced jailbreaks often survive post-attack quantization to 8-bit formats.